plain-crypto-js is a malicious npm package used in a March 2026 software supply-chain compromise involving poisoned Axios releases. It masqueraded as a legitimate JavaScript cryptography dependency and was inserted as a phantom dependency into compromised Axios versions so that npm would automatically execute its postinstall script during installation. Its sole operational purpose was to launch an obfuscated cross-platform malware chain rather than provide application functionality.
The package acted as a Remote Access Trojan deployment mechanism targeting Windows, macOS, and Linux systems, including developer workstations and CI/CD runners. Its postinstall logic decoded obfuscated strings at runtime, identified the host operating system, contacted attacker-controlled infrastructure, and retrieved platform-specific second-stage payloads. Reported payload behavior included host reconnaissance, periodic command-and-control beaconing, remote command execution, file and directory operations, process interaction, and the ability to run additional scripts or payloads. On Windows, reporting also describes persistence and in-memory execution techniques; across platforms, the malware used anti-forensics by deleting or replacing installation artifacts after execution to reduce evidence of compromise.
The campaign is associated with the compromise of an Axios maintainer account and the publication of malicious Axios versions that silently introduced plain-crypto-js into downstream dependency trees. Because Axios is widely used directly and transitively, the package posed particular risk to automated build environments and enterprise development ecosystems. Multiple reports characterize the malware as a cross-platform RAT or RAT dropper, and some reporting notes overlaps with WAVESHAPER and public attribution by major vendors to North Korea-linked activity, though such attribution should be treated as campaign-level rather than intrinsic to the package itself. Any environment that executed the malicious package should be considered compromised.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The npm package axios ... was compromised via maintainer account hijacking. Malicious versions 1.14.1 and 0.30.4 injected a dependency on plain-crypto-js@4.2.1, which contained a cross-platform Remote Access Trojan (RAT).
28 distinct techniques documented for this family, organized by ATT&CK tactic.
two malicious versions of Axios were published to npm after an attacker hijacked the lead maintainer's account... Both versions introduce a hidden dependency ( plain-crypto-js )
macOS: The dropper uses AppleScript... launches it silently via /bin/zsh. Windows: ... uses VBScript to fetch and execute a secondary PowerShell RAT script... Linux: The dropper uses the Node.js execSync command to download a Python RAT script...
Windows: The dropper searches for and copies the legitimate Windows PowerShell binary to %PROGRAMDATA%\wt.exe. It then uses VBScript to fetch and execute a secondary PowerShell RAT script, which is subsequently executed by wt.exe.
macOS: The dropper uses AppleScript to download a C++ compiled Mach-O binary, saves it to /Library/Caches/com.apple.act.mond, makes it executable and launches it silently via /bin/zsh.
Windows: ... It then uses VBScript to fetch and execute a secondary PowerShell RAT script...
Linux: The dropper uses the Node.js execSync command to download a Python RAT script to /tmp/ld.py, running it in the background using the nohup command.
They added a phantom dependency called plain-crypto-js that ran a postinstall hook deploying cross-platform malware.
Once installed, npm automatically ran post-install scripts tied to the dependency.
The only change in both malicious Axios versions was a single new dependency: "plain-crypto-js": "^4.2.1" . This package is never imported in the Axios source - it exists solely to run a postinstall hook
This triggers npm's postinstall lifecycle hook, executing a heavily obfuscated Node.js dropper script named setup.js in the background.
a malicious dependency named "plain-crypto-js", an obfuscated dropper that deploys the WAVESHAPER.V2 backdoor
To make this outbound traffic look like benign npm registry requests, it appends platform-specific paths: packages.npm[.]org/product0 for macOS ... All the RAT variants use a hard-coded... user-agent string spoofing Internet Explorer 8 on Windows XP
The C2 server accepts the same four commands from the attacker: kill (self-terminate) runscript (execute shell/script commands) peinject (drop and execute binary payloads) rundir (enumerate directories)
After launching the payload, the dropper erases all evidence - deleting itself, removing the malicious package.json , and swapping in a pre-staged clean manifest.
T1070.004 Indicator Removal: File Deletion setup.js self-deletes, removes package.json, swaps in clean package.md stub
After launching the second-stage payload, the installer logic removes its own loader ( setup.js ) and removes the manifest ( package.json ) that contained the install trigger. It then renames package.md to package.json , leaving behind a clean-looking manifest
The only change in both malicious Axios versions was a single new dependency: "plain-crypto-js": "^4.2.1" . This package is never imported in the Axios source - it exists solely to run a postinstall hook
This triggers npm's postinstall lifecycle hook, executing a heavily obfuscated Node.js dropper script named setup.js in the background.
During execution, the malware contacts command-and-control (C2) infrastructure at sfrclak[.]com to deliver platform-specific payloads, then deletes itself and replaces its package.json with a clean version to evade detection.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious phantom dependency added to compromised Axios releases. Its postinstall script runs setup.js, which acts as the initial dropper for the cross-platform RAT and then removes evidence by deleting files and restoring a clean package manifest.
A malicious package payload referenced in comparison to the main incident; it contained a cross-platform RAT delivered through the axios npm supply-chain compromise.
Malicious dependency injected during the Axios supply-chain compromise; it installed a remote access trojan on impacted environments.
A malicious npm package used in the Axios supply-chain compromise. It executes a postinstall script that drops a cross-platform remote access trojan for macOS, Windows, and Linux, performs reconnaissance, establishes persistence, communicates with a live C2 server, and includes self-deletion for evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.